8.8
CVE-2025-63409
- EPSS 0.12%
- Veröffentlicht 24.02.2026 00:00:00
- Zuletzt bearbeitet 26.02.2026 19:42:40
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Privilege escalation and improper access control in GCOM EPON 1GE C00R371V00B01 allows remote authenticated users to modify administrator only settings and extract administrator credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gcomtw ≫ Gcom Epon 1ge Firmware Versionc00r371v00b01
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.304 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.